Cybersecurity Roles and Responsibilities

Purpose

This document defines the main cybersecurity responsibilities within the company.

One person may perform several roles in a smaller company. The important point is that each responsibility has a clear owner.

Leadership

Leadership is responsible for:

  • Approving cybersecurity priorities
  • Providing appropriate resources
  • Reviewing significant cyber risks
  • Approving major risk acceptance decisions
  • Supporting incident response decisions
  • Ensuring cybersecurity is treated as a business responsibility

Primary owner: ____________________

Backup: ____________________

Cybersecurity Coordinator

The cybersecurity coordinator is responsible for:

  • Coordinating the cybersecurity playbook
  • Maintaining the Master Action Tracker
  • Coordinating risk reviews
  • Following up on security actions
  • Coordinating incident preparedness
  • Maintaining key security contacts
  • Preparing leadership updates

Primary owner: ____________________

Backup: ____________________

IT / Technical Owner

The IT or technical owner is responsible for:

  • Device and system security
  • Patch management
  • Endpoint protection
  • Secure configuration
  • Account administration
  • MFA implementation
  • Logging and monitoring
  • Backup operations
  • Technical incident containment and recovery

Primary owner: ____________________

Backup / MSP: ____________________

Data and System Owners

Business owners of important systems and data are responsible for:

  • Confirming who requires access
  • Approving access where appropriate
  • Reviewing access periodically
  • Identifying business criticality
  • Supporting recovery priorities
  • Confirming restored systems work correctly

System / data owners should be recorded in the relevant inventory.

HR

HR is responsible for supporting:

  • Employee onboarding
  • Employee offboarding
  • Role changes
  • Security training coordination
  • Employee-related incident handling
  • Insider threat escalation where appropriate

HR owner: ____________________

Finance

Finance is responsible for:

  • Payment verification controls
  • Bank-detail change verification
  • Financial system access approval
  • Fraud escalation
  • Supporting investigation of payment-related incidents

Finance owner: ____________________

Managers

Managers are responsible for:

  • Approving appropriate employee access
  • Reporting role changes promptly
  • Supporting secure onboarding and offboarding
  • Escalating suspicious activity
  • Preventing unsafe workarounds
  • Reinforcing cybersecurity expectations with their teams

Employees and Contractors

All users are responsible for:

  • Protecting credentials
  • Using MFA correctly
  • Using approved systems and tools
  • Handling data appropriately
  • Keeping devices secure
  • Following security procedures
  • Reporting suspicious activity promptly
  • Reporting security mistakes immediately

Vendor / MSP Owner

A named internal person should own important third-party relationships.

Responsibilities include:

  • Approving vendor access
  • Knowing what systems the vendor can access
  • Maintaining vendor contacts
  • Reviewing vendor access
  • Confirming access is removed when no longer required
  • Escalating vendor-related security issues

Owner: ____________________

Incident Response Lead

The incident response lead is responsible for:

  • Activating the incident response process
  • Coordinating triage
  • Maintaining the incident record
  • Coordinating containment
  • Escalating to leadership
  • Managing external technical support
  • Ensuring decisions are documented
  • Handing the incident into recovery and review

Primary incident lead: ____________________

Backup incident lead: ____________________

Recovery Lead

The recovery lead is responsible for:

  • Coordinating restoration
  • Following recovery priorities
  • Confirming trusted restore sources
  • Coordinating technical and business validation
  • Tracking recovery status
  • Handing completed recovery into post-incident review

Primary recovery lead: ____________________

Backup: ____________________

Security Awareness Owner

The security awareness owner is responsible for:

  • Planning employee training
  • Tracking completion
  • Coordinating role-based training
  • Running or arranging simulations and exercises
  • Updating training after incidents and near misses

Owner: ____________________

Review Frequency

Cybersecurity ownership should be reviewed:

  • At least annually
  • When key personnel change
  • When the MSP or major vendors change
  • After significant incidents
  • When important business systems or responsibilities change

Practical Rule

Every important cybersecurity responsibility should have one clearly accountable person and a backup wherever practical.